Almost the entire conversation about the EU AI Act and critical national infrastructure concerns high-risk systems. The Act's high-risk classification captures AI used in critical infrastructure management and a range of decision-support functions, and it imposes substantial obligations: conformity assessment, technical documentation, risk management systems, human oversight, registration. CNI operators preparing for the Act are, overwhelmingly, preparing for the high-risk system requirements, and they are right to take those requirements seriously.
But the high-risk system requirements are the part of the Act that organisations can see coming. They are visible, well-defined, and attached to identifiable systems that the organisation knows it operates. The Act's real enforcement problem for CNI operators lies elsewhere: in the prohibited practices that came into force first, in the general-purpose AI obligations that cut across the organisation, and above all in the AI the organisation is using without knowing it has brought the Act into play. The enforcement exposure is not in the high-risk systems the organisation is carefully governing. It is in the systems it is not.
The Sequence That Was Missed
The EU AI Act did not come into force all at once, and the sequence matters in a way that has been widely underappreciated. The Act's prohibitions on certain AI practices came into force first, in February 2025, ahead of the high-risk system obligations. These prohibitions ban specific uses of AI outright: certain kinds of biometric categorisation, social scoring, manipulation, and emotion recognition in defined contexts, among others. The general-purpose AI model obligations followed, in August 2025. The high-risk system obligations reach full application in August 2026, later than the provisions that received less attention.
This sequence means that the Act has been partly in force, and partly enforceable, for longer than many CNI operators have been treating it as a live obligation. Organisations focused on the August 2026 high-risk deadline have, in some cases, overlooked the prohibitions and GPAI obligations that were already enforceable. The mental model of the Act as a future obligation, arriving in August 2026, is wrong. Parts of it have been in force and enforceable since early 2025, and exposure under those parts has been accumulating while attention was directed at the later deadline.
The Prohibited Practices Exposure
The prohibited practices are the most acute version of this exposure, because they are absolute and because CNI operators may be engaged in them without recognition. A prohibition is not a requirement to be managed. It is a line not to be crossed. There is no conformity assessment, no documentation that makes a prohibited practice acceptable, no risk management that brings it into compliance. If an AI system engages in a prohibited practice, it is unlawful, and the consequence is enforcement rather than remediation. The prohibitions carry the Act's highest penalties precisely because they concern uses that the Act regards as unacceptable rather than merely risky.
The exposure for CNI operators arises because some prohibited practices can be engaged in inadvertently, through AI systems acquired or deployed without the recognition that they touch a prohibition. An emotion recognition capability embedded in a customer interaction system. A biometric categorisation function in a security or access system. A behavioural analysis tool that crosses into prohibited manipulation. These are not exotic systems. They are the kind of AI-enabled functionality that finds its way into CNI operations through procurement of broader systems, where the AI component and its regulatory status were not the focus of the purchasing decision.
An operator that has deployed such functionality without recognising it has crossed a prohibition is in the worst position the Act creates: engaged in an unlawful practice, accruing exposure to the Act's highest penalties, without any of the governance, documentation, or awareness that would even allow it to recognise the problem. The high-risk system requirements at least announce themselves; an organisation knows when it is deploying a high-risk system and can prepare. The prohibited practices exposure can exist entirely unrecognised, which is what makes it the Act's sharpest enforcement risk.
The General-Purpose AI Problem
The general-purpose AI obligations create a different version of the same recognition problem, distributed across the organisation rather than concentrated in specific systems. General-purpose AI models, including the large language models and foundation models that have proliferated through organisations since 2023, carry obligations under the Act, and models with systemic risk carry additional ones. The difficulty for CNI operators is that GPAI usage is rarely concentrated, governed, or even fully known. These models have entered organisations through countless routes: embedded in productivity tools, accessed through commercial services, integrated into bespoke applications, used directly by staff through public interfaces.
This is the shadow AI problem in its regulatory form. The Act's GPAI obligations apply to usage the organisation may not have mapped, governed, or in some cases be aware of. An operator confident that it has addressed the Act through its high-risk system programme may have a substantial unaddressed GPAI exposure sitting in the productivity tools, commercial services, and staff practices that the high-risk programme never examined. The enforcement risk is in the part of the AI estate the organisation does not see, not the part it is carefully governing.
Why the High-Risk Focus Is a Trap
The concentration on high-risk systems is not wrong, but it creates a trap, because it directs the organisation's attention and resources toward the visible, governable part of the Act and away from the parts where its actual exposure is greatest. The high-risk systems are knowable. The organisation can identify them, scope the requirements, build the conformity assessments and documentation, and complete the work to an evidenced standard. This is satisfying and it is necessary. It also creates a sense of having addressed the Act that is dangerously incomplete, because the prohibited practices and GPAI exposures, which are harder to find and may be larger, remain unaddressed beneath the confidence that the high-risk programme generates.
The organisations that understand this are inverting the usual priority. They are mapping their actual AI estate, all of it, including the embedded functionality, the commercial services, and the staff practices, before they assume they know what the Act requires of them. They are looking specifically for the prohibited practices exposure that can exist unrecognised, and for the distributed GPAI usage that the high-risk programme would never have found. They are treating the visibility problem, knowing what AI they are actually running, as the first task, because the Act's requirements cannot be met for systems the organisation has not discovered.
The EU AI Act's enforcement problem, for CNI operators, is not the high-risk systems they are governing carefully. It is the AI they have not yet found. The high-risk system requirements are the part of the Act that announces itself. The exposure that will produce the most enforcement is the part that does not, and the organisations preparing only for the announced part are preparing for the wrong problem.
